Live data from Hacker News

CISA Alert: Water Sector PLC Targeting

censys.com

51–60 of 78 posts

Re: CISA Alert: Water Sector PLC Targeting

#51
post #17

Earlier quoted context omitted.

It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..

I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)

If.

Re: CISA Alert: Water Sector PLC Targeting

#52

Earlier quoted context omitted.

Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.

“Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.

Not really. Just patch and reboot. Pretty simple.

Re: CISA Alert: Water Sector PLC Targeting

#53
post #17

> Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts). Describe the network security of the industrial automation industry and their customers in a single statement. Lol.

It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..

Used to drive me mad that the clipper terminals in the SF Caltrain station used dial up, in 2017!

Re: CISA Alert: Water Sector PLC Targeting

#55

Earlier quoted context omitted.

I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)

Dial up into an air gapped network defeats the purpose of being air gapped. I would think the bare minimum standard is that there is no way to change anything in the control systems without being physically present at the facility, past it's physical security boundary.

Is there reason to assume someone even tried to air gap it?

Re: CISA Alert: Water Sector PLC Targeting

#56

Earlier quoted context omitted.

So the federal government should be responsible for every rinky-dink water well in Bumblefuck, Minnesota? > failed to anticipate not only these infrastructure breach They've been warning them for close to two decades. Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.

The federal government makes sure everyone who sends a venmo for $60 pays taxes on it so yeah I think securing our national infrastructure is not an unreasonable expectation.

There's no "national infrastructure" for water. Aside from what the EPA does, it isn't within the remit of the federal government to manage municipality water systems.

Re: CISA Alert: Water Sector PLC Targeting

#57

Earlier quoted context omitted.

The federal government makes sure everyone who sends a venmo for $60 pays taxes on it so yeah I think securing our national infrastructure is not an unreasonable expectation.

There's no "national infrastructure" for water. Aside from what the EPA does, it isn't within the remit of the federal government to manage municipality water systems.

My wording was ambiguous. “national infrastructure” can refer to either the infrastructure in our nation or infrastructure managed by the federal government. I meant the former.

Re: CISA Alert: Water Sector PLC Targeting

#58

Earlier quoted context omitted.

“Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.

Not really. Just patch and reboot. Pretty simple.

can't reboot, the machinists have the windows sized and positioned on screen just like they like them since 1997, so if you reboot it will cause downtime

Re: CISA Alert: Water Sector PLC Targeting

#59

Earlier quoted context omitted.

It’s the same regulatory/incentive toolbox as any industry, including possibly accepting lower security standards for tiny treatment plants just like we accept less security for podunk airports. > make the feds do it National Security has always been a federal government responsibility. You make it sound like I’m expecting the federal government to take on some new responsibility. If the federal government starts a w…

National Security has always been a federal government responsibility yes. But what does that fundamentally mean for boots on the ground? NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so. I agree that in theory this would not be a…

> IT does not equal OT

I'll say, you should see the hours I have to work sometimes. Honestly I've rarely seen IT jobs pay OT.

Re: CISA Alert: Water Sector PLC Targeting

#60

> Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts). Describe the network security of the industrial automation industry and their customers in a single statement. Lol.

And how many more are on the same internal networks as dozens or hundreds of ordinary Windows desktops on which municipal workers are checking their email? Hardly better.
Post reply on HN